1. Introduction
This Data Processing Agreement ("DPA") supplements the Terms of Use and Privacy Policy. It governs how Syntr Technologies Pvt. Ltd. ("Syntr", "Data Processor") processes personal data on behalf of customers ("Data Controller") in compliance with GDPR, India's DPDP Act, and other applicable data protection laws.
This DPA applies when you use Syntr to process personal data of your customers, subscribers, or other individuals.
2. Roles & Responsibilities
| Party | Role | Responsibilities |
|---|---|---|
| Customer | Data Controller |
|
| Syntr | Data Processor |
|
3. Processing Instructions
- Syntr processes personal data only on documented instructions from the Data Controller
- Processing is limited to providing email marketing services as specified in the Terms of Use
- Syntr will not process data for any other purpose without prior written consent
- If required by law to process data differently, Syntr will notify the Data Controller before processing
4. Security Measures
Syntr implements appropriate technical and organizational measures to protect personal data:
- Encryption: TLS 1.2+ in transit, AES-256 at rest
- Access controls: Role-based access, least-privilege principle
- Regular audits: Security assessments and penetration testing
- Incident response: Procedures for detecting and responding to security incidents
See our Security Policy for detailed security measures.
5. Data Breach Notification
In the event of a personal data breach, Syntr will:
- •Notify the Data Controller within 72 hours of becoming aware of the breach
- •Provide detailed information about the nature of the breach, categories of data affected, and likely consequences
- •Describe measures taken or proposed to address the breach
- •Assist the Data Controller in notifying data subjects if required by law
6. Sub-Processors
Syntr may engage sub-processors to provide services. We ensure that:
- Sub-processors are disclosed transparently in our documentation
- Sub-processors are contractually bound to the same data protection obligations
- We will notify you of any new sub-processors (you may object within 30 days)
- Sub-processors include: email delivery providers, cloud infrastructure, analytics providers
7. Assistance with Compliance
Syntr will assist the Data Controller with:
- GDPR/DPDP compliance: Providing necessary information and documentation
- Data subject requests: Assisting with access, correction, deletion requests
- Data protection impact assessments: Providing information about processing activities
- Regulatory inquiries: Cooperating with supervisory authorities
8. Data Retention & Deletion
- •Data is retained only as long as necessary to provide services
- •Upon termination, data is deleted within 30-90 days unless retention is required by law
- •You may request earlier deletion by contacting support
- •Backups may be retained longer for security and legal compliance purposes
9. International Transfers
If personal data is transferred outside the EEA or India, Syntr ensures appropriate safeguards:
- •Standard contractual clauses (SCCs) approved by supervisory authorities
- •Adequacy decisions where applicable
- •Other legally recognized transfer mechanisms
10. Audit Rights
The Data Controller has the right to audit Syntr's compliance with this DPA, subject to:
- •Reasonable notice (at least 30 days)
- •Confidentiality obligations and non-disclosure agreements
- •Audits conducted during normal business hours
- •Alternatively, Syntr may provide third-party audit reports (SOC 2, ISO 27001) where available
11. Contact
For questions about this DPA, contact us at:
Data Protection Officer: dpo@syntr.com
Legal Team: legal@syntr.com
Support: support@syntr.com
